Privacy & Security Analyst

Health Sciences North

$93K — $110K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Law, Business, Technology, or related field required.
  • Preference for certification as a Certified Information Privacy Professional (CIPP) or similar designation.
  • Completion of Ministry of Labour 'Worker Health and Safety Awareness in 4 Steps' training required.
  • At least three years of experience in Privacy, Compliance, Risk Management, or Information Security in healthcare required.
  • Demonstrated understanding of Ontario and Canadian privacy laws vital.

Responsibilities

  • Consult and recommend on compliance with privacy legislation.
  • Identify and evaluate privacy risks to create mitigation strategies.
  • Investigate privacy breaches and lead response efforts.
  • Address privacy complaints from internal and external sources.
  • Develop and enforce privacy policies according to best practices.
  • Create training programs to foster privacy awareness throughout HSN.
  • Conduct privacy audits and assessments, ensuring compliance.

Benefits

  • Full-time temporary position until March 2027.
  • Opportunities for professional development and training.
  • Engagement in impactful privacy work with patient data.
  • Contributing to regional healthcare privacy practices.
  • Work within a supportive team-focused environment.
Full Job Description
Competition #

10313

Job Title

Privacy & Security Analyst

Department

Privacy & Information Security

Status

Temporary (July 2026 - March 2027)

Work Type

Full-time

Affiliation

Non Union

Shift Assignment

Days

Bilingualism Required

No

Police Check Requirement

Criminal Record and Judicial Matters Check

Site

Sudbury Outpatient Centre- Non Union Non Management

Salary Information

$44.96 - $52.90 / hour

Application Closing Date

July 1, 2026

KEY FUNCTION:

Ensure compliance with legislation and adherence to industry standards by supporting the Privacy and Information Security practices of HSN as both a Health Information Custodian and Health Information Network Provider (HINP).

REPORTING:

Under the general direction of the Manager, Access to Information and Privacy.

DUTIES:
  1. Provide consultation and recommendations; ensure compliance with existing privacy access to information legislation and for new and emerging federal and provincial legislations.
  2. Identify, report, analyze, and evaluate privacy risk to develop and implement mitigation mechanisms that support patients and HSN.
  3. Respond to reported privacy and information security breaches, investigate and lead breach responses, and make recommendations for corrective action within HSN and for regionally shared information systems.
  4. Respond to privacy complaints from internal and external sources.
  5. Develop and maintain privacy and information security policies, procedures, and work standards according to generally accepted privacy and information standards and best practices within HSN and for regionally shared information systems.
  6. Develop privacy materials, conduct privacy training programs, and promote privacy and information security awareness (e.g. face-to-face training, management of online instructional information, and print media) within HSN and with related entities associated with HSN.
  7. Conduct and report on Privacy Impact Assessments (PIA), organizational privacy attestations, and privacy audits/reviews.
  8. Determine and align improvement projects with HSN's Strategic Plan; monitor and adjust to achieve goal outcomes.
  9. Contribute to learner development by providing academic support, mentorship, preceptorship and supervision as required.
  10. Participate in education and training specific to current, relevant federal and provincial health and safety legislation, standards and guidelines.
  11. Educate and promote health, safety and wellness in the work place.
  12. Represent the department or program on various committees and in meetings as required.
  13. Perform other duties as required.


QUALIFICATIONS

EDUCATION AND TRAINING:
  1. Minimum of a four (4) year Bachelor's Degree in Law, Business, Technology, or in a related field, from an accredited university.
  2. Certification as a Certified Information Privacy Professional (CIPP) or a related privacy/information security designation is preferred.
  3. Ministry of Labour "Worker Health and Safety Awareness in 4 Steps" training certificate is required.


EXPERIENCE:
  1. Minimum of three (3) years' experience working in a Privacy, Compliance, Risk Management or Information Security department within a health care environment.


KNOWLEDGE/SKILLS/ABILITIES:
  1. Demonstrated knowledge of Ontario and Canadian privacy laws, including Personal Health Information Protection Act (PHIPA), Freedom of Information and Protection of Privacy Act (FIPPA), and Personal Information Protection and Electronic Documents Act (PIPEDA).
  2. Demonstrated ability to interpret and apply legislation, policy, and precedent.
  3. Demonstrated knowledge of privacy and information security standards, including Generally Accepted Privacy Principles (GAPP), National Institute of Standards and Technology (NIST), and International Organization for Standardization (ISO).
  4. Demonstrated ability to analyze and interpret privacy and information security data.
  5. Demonstrated ability to manage conflict and facilitate problem-solving in difficult situations.
  6. Demonstrated excellent judgment and proven analytical skills.
  7. Demonstrated training, experience or utilization of lean methodology for process improvement.
  8. Demonstrated ability to independently identify issues, plan improvements, measure success and continue improvement.
  9. Demonstrated excellent computer skills with proficiency in Microsoft Office software (e.g. Word, Excel, Power Point and Outlook) and patient information systems.
  10. Demonstrated superior interpersonal and communication skills, both written and verbal.
  11. Demonstrated ability to manage routine correspondence, multiple tasks/projects, diversified workload and rapidly changing priorities and challenging deadlines.
  12. Demonstrated discretion and maturity when handling confidential information.
  13. Demonstrated commitment to the safety of co-workers and patients.


PERSONAL SUITABILITY:
  1. Successful Criminal Records and Judicial Matters Check (CRJMC) is required.
  2. Proven ability to work independently and in a team environment.
  3. Demonstrated ability to perform with minimal supervision; to prioritize duties.
  4. Demonstrated commitment to ongoing professional development.
  5. Demonstrated professionalism in dealing with confidential and sensitive issues.
  6. Demonstrated positive work record and excellent attendance record.
  7. Ability to meet the physical and sensory demands of the job.
  8. Ability to travel between local sites.


Selection Process: Candidates will be selected for this position on the basis of their skill, ability, experience and qualifications as identified in the resume and completed Application Form submitted. The Hospital reserves the right to conduct a formal interview where required. This posting is for an existing vacancy.

HSN THANKS ALL APPLICANTS.
ONLY THOSE SELECTED FOR INTERVIEWS WILL BE CONTACTED.
WE WILL NOT ACCEPT APPLICATIONS AFTER THE CLOSING DATE AND TIME.

Similar Jobs

More Jobs at Health Sciences North

More Healthcare Jobs

Find similar Privacy & Security Analyst jobs: